Denial of Service Vulnerability in Cisco Meeting Server Web Admin Interface
CVE-2018-0371

6.5MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
21 June 2018

Summary

A vulnerability in the Web Admin Interface of Cisco Meeting Server permits authenticated remote attackers to induce a denial of service (DoS) condition. This issue stems from inadequate validation of incoming HTTP requests. By crafting and sending a specifically designed HTTP request to the vulnerable interface, an attacker could exploit the flaw, potentially causing the system to restart. This action terminates all active calls, thereby disrupting services on the affected Cisco Meeting Server models, including the Acano X-Series, and the Cisco Meeting Server 1000 and 2000.

Affected Version(s)

Cisco Meeting Server unknown Cisco Meeting Server unknown

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.